← Back to Controls

P2P-12

Business Process:
Procure to Pay
Sub-Process:
Non-PO Invoice
Control Type:
Detective
Execution Type:
Manual
Effective Date:
July 21, 2026

Control Description

Management periodically reviews the OpenText VIM authorization matrix to verify that users are assigned appropriate approval limits for non-PO invoices.

Risk

Users could retain excessive or unauthorized approval limits, allowing fraudulent or unapproved non-PO expenses to be processed and paid without proper oversight.

Implementation Details

• Authorization Matrix Definition: The OpenText VIM authorization matrix is housed in transaction /n/OPT/AR_COA (Chart of Authority), which sets user approval limits, monetary thresholds, and organizational scopes.

• Periodic Review Control: Management periodically executes a review of this matrix to ensure users maintain appropriate approval limits aligned with current job responsibilities and segregation of duties (SoD).

• Audit Evidence & Documentation: Operating the control requires retaining documented evidence of the review, such as a signed-off snapshot/export of the COA configuration or ticketing approvals for any limit modifications made during the period.

Test Procedures

Test of Design

1- Inquiry & Walkthrough: Inquire with AP Management and IT/Security owners to understand the frequency (e.g., quarterly) and methodology for reviewing user approval limits in transaction /n/OPT/AR_COA.

Test of Operating Effectiveness

1- Sample Selection: Select a sample of review periods (e.g., 2 quarterly reviews) completed during the audit period.
2- Evidence Inspection: For each sampled review, inspect the documented COA export and formal management sign-off (e.g., signed PDF or ticket approval) confirming timely review.